Security news.
Today's cybersecurity landscape is marked by urgent warnings about actively exploited vulnerabilities and ongoing campaigns. CISA has added critical flaws in Oracle WebLogic and Gitea to its KEV catalog, emphasizing the need for immediate patching. Meanwhile, cyber actors continue to leverage phishing, compromised infrastructure, and AI-assisted methods to breach organizations globally.
CISA Adds Gitea Code Injection Flaw to KEV Catalog
CISA has added CVE-2026-60004, a Gitea Code Injection Vulnerability, to its Known Exploited Vulnerabilities Catalog, urging federal agencies to patch immediately due to active exploitation.
Actively Exploited Oracle WebLogic Flaw Allows Unauthenticated Data Access
CISA has added the maximum-severity CVE-2026-21962, impacting Oracle HTTP Server and Oracle WebLogic Server, to its KEV catalog, citing evidence of active exploitation for critical data access.
Hackers Compromise Over 270 Zimbra Servers in Ongoing Attacks
Threat actors have exploited a high-severity Zimbra Collaboration Suite (ZCS) vulnerability to achieve remote code execution on over 270 Zimbra instances.
Attackers Target miniOrange SAML Flaws for WordPress Admin Access
Bad actors are actively exploiting two severe unauthenticated authentication bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981) in the Xecurify miniOrange SAML 2.0 Single Sign On plugin to gain administrative access to WordPress sites.
Mirage2FA Phishing Campaign Bypasses Microsoft 365 MFA for 4,500+ Companies
The Mirage2FA phishing-as-a-service toolkit has affected thousands of US and EU companies by abusing legitimate Microsoft 365 login flows to bypass two-factor authentication.
Massive DDoS Attack Disrupts Norway's Government Digital Services
A large distributed denial-of-service (DDoS) attack has been ongoing since Monday, impacting Norway's shared government digital infrastructure and affecting public sector services.
Malicious Webpage Could Poison Local AI Models Behind NVIDIA NemoClaw
Oasis Security has revealed a flaw in NVIDIA NemoClaw that allows an attacker-controlled webpage to take unauthenticated control of local Ollama instances and implant hidden instructions within AI models.
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has imposed new sanctions on Iranian cyber actors, citing an "unprecedented economic campaign" to sever financial ties supporting the regime and its enablers.